It creates the following folder:
%UserProfile%\Local Settings\Application Data\Bron.tok-24

It overwrites C:\Autoexec.bat with the following text:
"pause"

The worm creates the following registry entry so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"Bron-Spizaetus" = "C:\WINDOWS\PIF\CVT.exe"

It may modify some of the following registry entries:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\System\"DisableRegistryTools" = "1"
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\System\"DisableCMD" = "2"
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\Explorer\"NoFolderOptions" = "1"

It adds a task to the Windows scheduler to execute the following file at 5:08 PM every day:
%UserProfile%\Templates\A.kotnorB.com